A mass production method for an encrypted mobile SSD

The method addresses security and efficiency issues in encrypted SSD production by using existing SSD tools for offline key binding and authentication, enhancing production security and efficiency.

CN114664357BActive Publication Date: 2025-07-15浙江元储科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111675074.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-31
Publication Date
2025-07-15
Estimated Expiration
2041-12-31

AI Technical Summary

Technical Problem

The mass production process of existing encrypted mobile SSDs needs to be certified and cooperated by host-side software, and the production process is lacking confidentiality and low efficiency.

Method used

Using two-level firmware download and U-shield binding algorithm, SSD and U-shield binding are bound on the production side through offline mode, U-shield verification algorithm is defined, and U-shield binding key is combined to achieve mass production of encrypted SSDs.

Benefits of technology

Improve the confidentiality and efficiency of the production process of encrypted mobile SSDs, and complete the update of internal encrypted bootloader and firmware by reusing the current SSD mass production tools.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114664357B_ABST
    Figure CN114664357B_ABST
Patent Text Reader

Abstract

The present invention discloses a mass production method for an encrypted mobile SSD, which includes preparing the internal storage space of the chip, downloading two-level firmware, binding a USB key, starting the firmware, checking the USB key, and initializing the data key. The internal storage space of the SSD disk's internal eFuse is used for preparing the internal storage space of the chip. The downloading of the two-level firmware includes the download of the Boot Loader and the download of the product firmware. The binding of the USB key includes setting KEYA, setting ZoneKey, and saving C_Primary_Key. By reusing the current mass production tool of the SSD, the present invention completes the update of the encrypted boot loader and firmware inside the SSD, defines the algorithm process for binding the USB key, binds the SSD and the USB key at the production end in an offline manner, defines the algorithm for verifying the USB key, combines the binding key of the USB key, and completes the authentication function of the encrypted SSD. By binding the USB key through offline encryption for production, the confidentiality and efficiency of the production process are greatly improved, and it has a certain application prospect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of mass production of national cryptographic mobile SSDs, and specifically provides a mass production method for encrypted mobile SSDs. Background Art

[0002] The existing mass production process of encrypted mobile SSDs requires authentication and cooperation of host software. The confidentiality of the production process is lacking and the efficiency is low. There is an urgent need to design a mass production method for encrypted mobile SSDs. Summary of the Invention

[0003] The present invention provides a mass production method for encrypted mobile SSDs with relatively high efficiency.

[0004] According to one aspect of the present invention, there is provided a mass production method for encrypted mobile SSDs, including:

[0005] Step 1, prepare the internal storage space of the chip: Prepare some storage spaces of the internal eFuse of the chip;

[0006] Step 2, download two-level firmware: The firmware mass production process of the encrypted mobile SSD adopts two-level firmware: Boot Loader and product firmware, and download Boot Loader and product firmware;

[0007] Step 3, bind the U shield: Use the same batch with the same KEYA and ZoneKey, set KEYA, the batch number can be set as required, set ZoneKey, the number of Zones can be configured as required, corresponding to the space for saving the ciphertext of Primary_Key, save C_Primary_Key. Since KEYA and ZoneKey are burned separately and have been burned during U shield binding, when saving C_Primary_Key, the verification of KEYA and ZoneKey is required. After passing the verification, save C_Primary_Key and Compare_Data;

[0008] Step 4, start the firmware: After the disk is powered on, load the firmware. First, check the legality of BootLoader, and then check the legality of the product firmware;

[0009] Step 5, check the U shield: After power on, it is necessary to first verify the correctness of KEYA, and other operations can be performed only after passing. The access to the Zone requires first verifying the correctness of ZoneKey. After the encrypted mobile SSD is powered on, first check the flag bit in the eFuse. If the flag bit is locked, read the EEPROM to obtain the primary key ciphertext C_Primary_Key;

[0010] Step 6, Initialize the data key: After the U shield legality check passes, obtain the primary key ciphertext C_Primary_Key saved in the U shield.

[0011] In some embodiments, the storage space of the internal eFuse of the SSD used in the internal storage space of the preparation chip: The two-stage firmware download includes Boot Loader download and product firmware download.

[0012] In some embodiments, the binding of the U shield includes setting KEYA, setting ZoneKey, and saving C_Primary_Key;

[0013] The internal storage space of the preparation chip is some storage space of the internal eFuse of the preparation chip.

[0014] In some embodiments, the two-stage firmware download is that the firmware mass production process of the encrypted mobile SSD adopts two-stage firmware, including Boot Loader and product firmware, and downloads Boot Loader and product firmware.

[0015] In some embodiments, the binding of the U shield is to use the same batch with the same KEYA and ZoneKey, set KEYA, the batch number can be set as needed, set ZoneKey, the number of the Zone is configured as needed, corresponding to the space for saving the Primary_Key ciphertext, save C_Primary_Key. Since KEYA and ZoneKey are separately burned and have been burned during U shield binding, when saving C_Primary_Key, verification of KEYA and ZoneKey is required. After the verification passes, save C_Primary_Key and Compare_Data.

[0016] The beneficial effects are as follows: The present invention completes the update of the internal encrypted bootloader and firmware of the SSD by reusing the current SSD mass production tool, defines the U shield binding algorithm process, binds the SSD and the U shield at the production end in an offline manner, defines the U shield verification algorithm, combines the U shield binding key, and completes the encrypted SSD authentication function. By binding the U shield in an offline encryption manner for production, the confidentiality and efficiency of the production process are greatly improved. Brief Description of the Drawings

[0017] Figure 1 It is a flowchart of a mass production method for an encrypted mobile SSD of the present invention;

[0018] Figure 2 It is a flowchart of BootLoader download in a mass production method for an encrypted mobile SSD of the present invention;

[0019] Figure 3 This is the flowchart for downloading the product firmware in the mass production method of an encrypted mobile SSD according to the present invention;

[0020] Figure 4 This is a schematic diagram of the generation method of KEYA in the mass production method of an encrypted mobile SSD according to the present invention;

[0021] Figure 5 This is a schematic diagram of the generation method of ZoneKey in the mass production method of an encrypted mobile SSD according to the present invention;

[0022] Figure 6 This is the verification flowchart of KEYA in the mass production method of an encrypted mobile SSD according to the present invention;

[0023] Figure 7 This is the verification flowchart of ZoneKey in the mass production method of an encrypted mobile SSD according to the present invention;

[0024] Figure 8 This is the flowchart of the U shield binding scheme for an encrypted mobile solid state drive in the mass production method of an encrypted mobile SSD according to the present invention;

[0025] Figure 9 This is the startup flowchart of the firmware in the mass production method of an encrypted mobile SSD according to the present invention;

[0026] Figure 10 This is the verification flowchart of KEYA in the mass production method of an encrypted mobile SSD according to the present invention;

[0027] Figure 11 This is the verification flowchart of ZoneKey in the mass production method of an encrypted mobile SSD according to the present invention;

[0028] Figure 12 This is the flowchart for determining the legality of the U shield and obtaining the primary key ciphertext in the mass production method of an encrypted mobile SSD according to the present invention;

[0029] Figure 13 This is the flowchart for generating the user data key in the mass production method of an encrypted mobile SSD according to the present invention. Detailed implementation manners

[0030] To make the technical means, creative features, achieved purposes and functions of the present invention easy to understand, the present invention will be further described below in conjunction with specific implementation manners.

[0031] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0032] Embodiment 1

[0033] As Figure 1 shown, a mass production method for an encrypted mobile SSD includes preparing the internal storage space of the chip, downloading two levels of firmware, binding a U shield, starting the firmware, checking the U shield, and initializing the data key. The internal storage space of the SSD disk's internal eFuse is used for preparing the internal storage space of the chip. Downloading two levels of firmware includes Boot Loader download and product firmware download. Binding the U shield includes setting KEYA, setting ZoneKey, and saving C_Primary_Key;

[0034] The mass production method for a national cryptographic mobile SSD includes the following steps:

[0035] Step 1, prepare the internal storage space of the chip: Prepare some storage space of the internal eFuse of the chip;

[0036] Step 2, download two levels of firmware: The firmware mass production process of the encrypted mobile SSD adopts two levels of firmware: Boot Loader and product firmware. Download Boot Loader and product firmware. The download process of Boot Loader is as shown in the appendix Figure 2 shown, including using an authorized tool to perform SM2 signature on BootLoader, downloading the BootLoader data packet through the mass production tool. The data packet includes Bootloader signature and SM2 public key. Call the SM3 program to calculate the digest of the public key. SM3 is set as the digest of the public key. Write the digest into the one-time programmable device inside the chip, that is, eFuse. Call the firmware encryption program, and perform encryption with SM4. Store the encrypted firmware in NAND Flash through the chip ID and eFuse. The download process of the product firmware is as shown in the appendix Figure 3 shown, including mass production loading BootLoader, using an authorized tool to perform SM2 signature on the firmware, downloading the plaintext firmware + signature value through the mass production tool, that is, the signature and the plaintext firmware. Call the firmware encryption program, and perform SM4 encryption through eFuse, chip ID + LOC_TRNG1. Store the encrypted firmware in NOR Flash. The ciphertext is the firmware + signature;

[0037] Step 3, Bind the U shield: Use the same batch with the same KEYA and ZoneKey. Set KEYA. The calculation process of KEYA is as shown in the appendix Figure 4 as follows. Calculate the SM3 digest through the public key + batch number to obtain KEYA. The batch number can be set as needed. Set ZoneKey. The calculation process of ZoneKey is as shown in the appendix Figure 5 as follows. Calculate the SM3 digest through the public key + Zone number to obtain ZoneKey. The number of the Zone is configured as needed, corresponding to the space for saving the Primary_Key ciphertext. Save C_Primary_Key. Since KEYA and ZoneKey are separately burned and have been burned during U shield binding, the verification of KEYA and ZoneKey is required when saving C_Primary_Key. The verification process of KEYA is as shown in the appendix Figure 6 as follows: Call the TRNG module to generate RandomA, call DX8_HostAuth to send RandbmA to the EEPROM, read: public key + batch number, calculate its SM3 digest, call lib_HastAuth to calculate Response based on RandomA and KEYA. If the verification passes, subsequent operations can be performed; if not, subsequent operations are prohibited. The verification process of ZoneKey is as shown in the appendix Figure 7 as follows: Call the TRNG module to generate Random B, read: public key + batch number one number, calculate its SM3 digest, call Dx8_VerifyZone to calculate Res based on RandomB and Zone Key. If the verification passes, subsequent operations can be performed; if not, subsequent operations are prohibited. After passing the inspection, save C_Primary_Key and Compare_Data according to the process shown in the appendix Figure 8 as follows. First, generate Primary_Key: Call the TRNG module to generate random data Random c, calculate the sM3 digest, Primary_Key[127:0], encrypt it with SM4-ECB, calculate MID_Hash: Read the SSD chip ID, calculate the sM3 digest MID_Hash[127:0]; Save Compare Data: Read LOC_TRNG_2 in the efuse, calculate the sM3 digest LTrng_Hash_2[127:0], and finally save C_Primary_Key: C_Primary_Key → encrypt with SM4-ECB → Compare Data; C_Primary_Key → EEPROM; encrypt with SM4-ECB → eFuse;

[0038] Step 4, Start the firmware: After the disk is powered on, the firmware loading process is as shown in the appendix Figure 9As shown in the figure, first check the legality of the BootLoader, then check the legality of the product firmware, and load the BootLoader: stare → run the BootROM → load the encrypted BootLoadar → decrypt with SM4 → SM2 public key + BootLoader → SM3 → digest; eFuse → chip ID → decrypt with SM4; eFuse → public key digest; compare whether the public key digest is the same as the digest. If the comparison fails, interrupt the loading. If the comparison is successful, perform SM2 signature verification. If the verification passes, run the BootLoader. If the verification fails, interrupt the loading. Run the BootLoader → import the encrypted firmware → encrypted text (firmware + signature) → decrypt the firmware → verify the legality of the firmware → perform SM2 signature verification; eFuse → chip ID + LOG_TRNG1 → decrypt with SM4 → firmware + signature → perform SM2 signature verification. If the SM2 signature verification passes, the verification is successful and the product firmware runs. If the verification fails, the terminal loading is interrupted.

[0039] Step 5: Check the U shield. After power-on, it is necessary to first verify the correctness of KEYA. Only after passing can other operations be performed. The verification process of KEYA is as attached Figure 10 As shown in the figure, to access the Zone, it is necessary to first verify the correctness of the ZoneKey. Call Dx8_HostAuth to send RandomA to the EEPROM → EEPROM; call the TRNG module to generate Random A → read: public key + batch number, calculate its SM3 digest → call Lib_HostAuth to calculate Response based on RandomA and KEYA. If the verification passes, perform subsequent operations. If the verification fails, prohibit subsequent operations. The verification process of the ZoneKey is as attached Figure 11 As shown in the figure, call the TRNG module to generate Random B → call DX8_VerifyZone to calculate Res based on RandomB and Zonekey; read: public key + batch number + Zone number, calculate its SM3 digest → call DX8_VerifyZone to calculate Res based on RandomB and Zonekey. If the verification passes, subsequent operations can be performed. If it fails, subsequent operations are prohibited. After the encrypted mobile SSD is powered on, first check the flag bit in the eFuse. If the flag bit is locked, follow the attached Figure 12The process shown reads the EEPROM, reads LoC_TRNG_2→SN saved in the chip→calculates the SM3 digest→LTmg_Hash_2[127:0]→encrypts using SM4-ECB; reads the SN of the EEP ROM, reads C_Primary_Key→EEPROM→c_Primary key→encrypts using SM4-ECB→Compares Data→if any one of Compare Data n in the SSD is equal, the comparison is correct and operations can continue, if the comparison is incorrect, subsequent operations are prohibited, and the ciphertext of the primary key C_Primary_Key is obtained;

[0040] Step six, initialize the data key: After the U shield legality check passes, obtain the ciphertext of the primary key C_Primary_Key saved in the U shield, and then generate the user data key according to the process shown in the appendix Figure 13 The process shown decrypts the primary key, reads the ID of the ssD chip, reads the SN of the EEPROM chip, calculates the SM3 digest, MID_Hash[127:o], c_Primary key, calls the SM4 decryption algorithm to obtain Primary_Key; generates Media_Key, calculates the SM3 digest through LoC_TRNG_3 to obtain Loc_Thash_3[255.0], and mixes and calculates Primary_Key with SM4-ECB to obtain SM4-XTS, and obtains the plaintext User Daa and the ciphertext User_Data.

[0041] Although the present invention has been specifically shown and described in conjunction with the preferred embodiments, those skilled in the art will make changes in the specific implementation manner and application scope without departing from the spirit and scope of the present invention defined by the appended claims, and all of them are within the protection scope of the present invention.

Claims

1. A mass production method for an encrypted mobile SSD, characterized in that, Including: Step 1, Prepare the internal storage space of the chip: Prepare some storage space of the eFuse inside the chip; Step 2, Download two-level firmware: The firmware mass production process of the encrypted mobile SSD adopts two-level firmware: Boot Loader and product firmware, and download Boot Loader and product firmware; Step 3, Bind the U shield: Use the same batch with the same KEYA and ZoneKey, set KEYA, the batch number can be set as needed, set ZoneKey, the number of the Zone is configured as needed, the space corresponding to save the Primary_Key ciphertext, save C_Primary_Key. Since KEYA and ZoneKey are burned separately and have been burned during U shield binding, when saving C_Primary_Key, the verification of KEYA and ZoneKey is required. After passing the verification, save C_Primary_Key and Compare_Data; Step 4, Start the firmware: After the disk is powered on, load the firmware. First, load BootLoader, and then check the legality of the product firmware; Step 5, Check the U shield: After power on, the correctness of KEYA needs to be verified first, and other operations can be performed only after passing. The access to the Zone needs to verify the correctness of ZoneKey first. After the encrypted mobile SSD is powered on, first check the flag bit in the eFuse. If the flag bit is locked, read the EEPROM to obtain the primary key ciphertext C_Primary_Key; Step 6, Initialize the data key: After the U shield legality check passes, obtain the primary key ciphertext C_Primary_Key saved in the U shield.

2. The mass production method of the encrypted mobile SSD according to claim 1, wherein, The storage space of the eFuse inside the SSD disk used for preparing the internal storage space of the chip: The download of the two-level firmware includes the download of Boot Loader and the download of product firmware.

3. The mass production method of the encrypted mobile SSD according to claim 1, characterized in that, The binding of the U shield includes setting KEYA, setting ZoneKey, and saving C_Primary_Key; The preparation of the internal storage space of the chip is to prepare some storage space of the eFuse inside the chip.

4. The mass production method of the encrypted mobile SSD according to claim 1, characterized in that, The download of the two-level firmware is that the firmware mass production process of the encrypted mobile SSD adopts two-level firmware, including Boot Loader and product firmware, and download BootLoader and product firmware.

5. The mass production method of the encrypted mobile SSD according to claim 1, characterized in that, The binding of the U shield is to use the same batch with the same KEYA and ZoneKey, set KEYA, the batch number can be set as needed, set ZoneKey, the number of the Zone is configured as needed, the space corresponding to save the Primary_Key ciphertext, save C_Primary_Key. Since KEYA and ZoneKey are burned separately and have been burned during U shield binding, when saving C_Primary_Key, the verification of KEYA and ZoneKey is required. After passing the verification, save C_Primary_Key and Compare_Data.

Citation Information

Patent Citations

  • Trusted boot method for joint full disk encryption on the basis of firmware and USB (Universal Serial Bus) key

    CN107679425A

  • Safe and controllable mass production method based on state secret chip

    CN111611602A